Information barriers compliance assistant (preview)
Article
This article explains how you can enable the information barrier (IB) compliance assistant for group-connected SharePoint sites. These sites are sites that don't have an associated team in Microsoft Teams. When the information barrier compliance assistant is enabled, users who don't match the segments specified on this site are automatically removed to ensure group membership honors configured information barrier policies. This configuration may help ensure your organization remains compliant with standards, policies, and compliance regulations.
PowerShell account must have directory administrator access for the tenant.
Enable the background compliance assistant
These steps create a new application in your organization's enterprise applications. For the compliance assistant to function properly, you must have explicitly added segments to a SharePoint site. Complete the following steps to enable the compliance assistant:
When prompted, sign in using your Office 365 work or school account.
In the Permissions requested dialog box, review the information, and select Accept. This action configures admin consent for the compliance assistant.
Verify a new application was created
To verify that a new application was properly created in your organization's enterprise applications, complete the following steps:
Log into portal.azure.com with directory administrator's credentials.
Select Manage Microsoft Entra ID.
Select Enterprise Applications in left navigation listing.
Search for the compliance assistant using 'M365' as the search term.
Select M365-Group-Compliance-Assistant from the list of search results.
On the M365-Group-Compliance-Assistant overview page, you can review application properties.
Select Permissions in the left-navigation pane to review the permissions that the application is authorized for.
In this example, the M365-Group-Compliance-Assistant is authorized to add/remove noncompliant information barrier users from your Microsoft 365 groups.
You can use audit log search in the Microsoft Purview compliance portal to search, review, and track audit log events for the M365-Group-Compliance-Assistant application. The audit activities associated with the compliance assistant are:
IB assistant removed group member: The IB noncompliant group member was removed from the group by the compliance assistant.
IB assistant removed group owner: The IB noncompliant owner was removed from the group by the compliance assistant.
Identified as IB non-compliant group: The segments on the group are non-IB compliant with each other.
To search the audit log for Microsoft 365 Groups activities, see Search the audit log.
Note
The compliance assistant runs periodically (every 24 hours). The assistant runs on group-connected SharePoint sites that do not have an associated team in Microsoft Teams. To enable the compliance assistant for SharePoint sites connected to Microsoft Teams, follow the instructions in the Define information barrier policies article.